#shiny #xss "#cross-site scripting" #httpOnly